
Certified Secure Software Lifecycle Professional
Domain 8Objective 1
Implement Software Supply Chain Risk Management (e.g., International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST)) CSSLP Practice Questions (Page 1)
Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
10%of the exam
Questions 1–5
- 1
What is the primary purpose of maintaining a software bill of materials (SBOM) for a product?
Select an answer first - 2
A developer wants to use a small utility library from a personal GitHub account. The library has no documentation, no releases, and the author has not responded to issues. What should the developer do?
Select an answer first - 3
A company wants to automate the detection of known vulnerabilities in its third-party components. They have an SBOM for each product. What should they do to continuously monitor for vulnerabilities?
Select an answer first - 4
A team is considering a component that has a known vulnerability, but the vulnerability is only exploitable if the component is used in a specific configuration that the team does not use. What should the team do?
Select an answer first - 5
Which factor is most important when assessing the risk of a third-party component that has not been updated in several years?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.